Content Domain 2: Security
Tasks
Task 2.1: Implement authentication and authorization mechanisms for applications and AWS services.
Skill 2.1.1: Implement identity federation.
Skill 2.1.2: Implement access control (for example, fine-grained permissions, security tokens, MFA).
Skill 2.1.3: Configure programmatic access to AWS.
Skill 2.1.4: Use presigned URLs to provide secure, time-limited access (for example, by using Amazon S3 and Amazon CloudFront).
Skill 2.1.5: Make authenticated calls to AWS services.
Skill 2.1.6: Define permissions for IAM principals (for example, users, roles, services) and resources.
Skill 2.1.7: Assume an IAM role.
Task 2.2: Implement encryption and manage sensitive data by using AWS services.
Skill 2.2.1: Apply encryption at rest and in transit.
Skill 2.2.2: Manage certificates by using AWS services (for example, AWS Certificate Manager, AWS Private CA).
Skill 2.2.3: Select and apply client-side or server-side encryption.
Skill 2.2.4: Use encryption keys to encrypt and decrypt data.
Skill 2.2.5: Generate certificates and SSH keys for development purposes.
Skill 2.2.6: Identify, mask, and limit access to sensitive data (for example, personally identifiable information [PII], protected health information [PHI]) by using AWS services.
Skill 2.2.7: Use secret management services to secure sensitive data.
Task 2.3: Identify and mitigate security risks associated with using and integrating AI services into application development.
Skill 2.3.1: Request and manage access to AI services.
Skill 2.3.2: Use data privacy controls to transmit data to AI services (for example, by using VPC endpoints to establish private connectivity, ensuring that inputs and outputs are not used to train AI models).
Skill 2.3.3: Filter and control AI model inputs and outputs (for example, by applying content filtering, sensitive information detection, PII/PHI redaction, denied topic policies, prompt injection and manipulation protection).
Skill 2.3.4: Secure AI agent interactions (for example, by using tool-use authorization, session isolation, human-in-the-loop approval flows for sensitive actions).
Skill 2.3.5: Protect sensitive content in monitoring logs during interactions with AI services.